URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.139.81/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3807142
URL: http://176.65.139.81/hiddenbin/boatnet.sh4
URL Status:Offline
Host: 176.65.139.81
Date added:2026-03-28 17:48:13 UTC
Last online:2026-04-13 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-03-28 17:49:12 UTC to abuse{at}stormindustries[dot]llc)
Takedown time:15 days, 23 hours, 44 minutes Bad (down since 2026-04-13 17:33:41 UTC)
Tags:elf mirai link SuperH ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-07n/aelf 1f990826615dde2397554929c3ce9ee3ef736b0152fc03d8a298336fa28b27c4n/aMirai
2026-04-05n/aelf 2e9a0babdb052ef2b863553e2a375090b32cc43230f421c92406c96746646425n/aMirai
2026-04-04n/aelf b7932979225b9b488aa7006b36c47c519814ad740d49db59aa59a7c69d2c89bbn/aMirai
2026-04-04n/aelf 36c606239d9ae977e2a2f3feb5e287568fab0b991421fa1c153cb81402079c7cn/aMirai
2026-03-28n/aelf 78e7832fb64f89645b65e7d32bb2b0ac2533c9250fcfbca0ffccb823c5f2e42bn/aMirai